Genie Agent Mode API Adds File Reasoning

Databricks GA'd Agent mode and opened its API, letting agents join tables with PDFs in Unity Catalog volumes. Power is real, so is the permission risk.

Databricks Genie Agents analyzing tables and volume files via Agent mode API streaming results
Agent mode now runs across tables and Unity Catalog volumes with API access via SSE.
Contents(3)

Databricks just gave Genie Agents the ability to reason over files, not just tables. The Sept. 2 update brings Genie Agent Mode API to every agent, along with file analysis on Unity Catalog volumes.

Companies working on this

StartupHub profiles of the companies this article names, with funding and a one-liner from our database.

Databricks
$190.0B
A unified data analytics and AI platform built on the lakehouse architecture.

Agent mode runs a multi-step loop that plans research, executes iterative queries, and delivers a cited report with visuals. Chat mode handles single lookups. Agent mode builds the analysis.

That loop no longer lives only in the UI. Developers can call Agent mode APIs to embed it in apps, chatbots, and scheduled reports, streaming responses via Server-Sent Events and pulling conversation history programmatically.

How the Genie Agent Mode API actually works

Think of a researcher who can open your file cabinet while querying the database. An agent builder attaches up to 10 Unity Catalog volumes containing PDFs, slide decks, and images, then a user asks a blended question like churn regions plus themes from exit surveys.

In Agent mode the agent retrieves the most relevant file content, reasons across files and governed tables, and answers in one conversation. Databricks says it respects Unity Catalog permissions and can use content search indexing to speed retrieval across large collections, which lowers latency but also makes sensitive content more discoverable if permissions are broad.

Why this matters and what is not fixed

Affected systems are any Genie Agent with volumes attached and any custom app using the new APIs. This is not a remote exploit, it requires legitimate access plus over-permissive volume grants.

The risk is prompt-driven exfiltration across unstructured data that was previously siloed. Visualization support via API means a single blended query can return tables and charts that combine restricted documents with warehouse data, and shared chats propagate those outputs to anyone with the link.

Mitigations exist. Unity Catalog permissions are enforced, content search must be configured, and builders can review Genie Code suggestions before saving instructions or SQL. Gaps remain. Databricks has not detailed file-type restrictions, indexing retention, or audit logging for file-grounded answers, and author review is optional.

This follows a clear governance push. The same week Databricks Unity Gateway cut $1.2M in agent waste by centralizing control, Genie now widens what agents can read. Builders should scope volumes narrowly, index only what is needed, and monitor shared conversation links.

© 2026 StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training requires a license. See our terms.
Daniel Singer

Written by

Daniel Singer

Editor, StartupHub.ai

Daniel Singer is the editor of StartupHub.ai, a technology expert and thought leader on AI and its applications across sectors, from fintech and healthcare to developer tooling and consumer software. He writes and tests the tools covered here thoroughly and regularly, and built StartupHub.ai to give founders, operators and buyers a clearer read on what they are actually being sold.

More from Daniel Singer

Startups in this story

Profiles for the companies named above.